Repository navigation
feat(auto): Autonomous Repository Management System #233
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| * @NITISH-R-G |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,29 @@ | ||
| frontend: | ||
| - changed-files: | ||
| - any-glob-to-any-file: 'web/**/*' | ||
|
|
||
| backend: | ||
| - changed-files: | ||
| - any-glob-to-any-file: 'ev_grid_oracle/**/*' | ||
| - any-glob-to-any-file: 'server/**/*' | ||
|
|
||
| training: | ||
| - changed-files: | ||
| - any-glob-to-any-file: 'training/**/*' | ||
|
|
||
| tests: | ||
| - changed-files: | ||
| - any-glob-to-any-file: 'tests/**/*' | ||
|
|
||
| docs: | ||
| - changed-files: | ||
| - any-glob-to-any-file: 'docs/**/*' | ||
| - any-glob-to-any-file: '*.md' | ||
|
|
||
| tools: | ||
| - changed-files: | ||
| - any-glob-to-any-file: 'tools/**/*' | ||
|
|
||
| github-actions: | ||
| - changed-files: | ||
| - any-glob-to-any-file: '.github/**/*' |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,31 @@ | ||
| name: CI Testing | ||
|
|
||
| on: | ||
| push: | ||
| branches: [ "main", "master" ] | ||
| pull_request: | ||
| branches: [ "main", "master" ] | ||
|
|
||
| jobs: | ||
| test: | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
|
|
||
| - name: Set up Python | ||
| uses: actions/setup-python@v5 | ||
| with: | ||
| python-version: '3.12' | ||
| cache: 'pip' | ||
|
|
||
| - name: Pull Git LFS objects | ||
| run: git lfs pull | ||
|
|
||
| - name: Install dependencies | ||
| run: | | ||
| python -m pip install --upgrade pip uv | ||
| uv pip install --system -e ".[dev,demo]" | ||
|
|
||
| - name: Run Pytest | ||
| run: | | ||
| uv run pytest tests/ |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,40 @@ | ||
| name: "CodeQL Analysis" | ||
|
|
||
| on: | ||
| push: | ||
| branches: [ "main", "master" ] | ||
| pull_request: | ||
| branches: [ "main", "master" ] | ||
| schedule: | ||
| - cron: '27 15 * * 0' | ||
|
|
||
| jobs: | ||
| analyze: | ||
| name: Analyze | ||
| runs-on: ubuntu-latest | ||
| permissions: | ||
| actions: read | ||
| contents: read | ||
| security-events: write | ||
|
|
||
| strategy: | ||
| fail-fast: false | ||
| matrix: | ||
| language: [ 'python', 'javascript' ] | ||
|
|
||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v4 | ||
|
|
||
| - name: Initialize CodeQL | ||
| uses: github/codeql-action/init@v3 | ||
| with: | ||
| languages: ${{ matrix.language }} | ||
|
|
||
| - name: Autobuild | ||
| uses: github/codeql-action/autobuild@v3 | ||
|
|
||
| - name: Perform CodeQL Analysis | ||
| uses: github/codeql-action/analyze@v3 | ||
| with: | ||
| category: "/language:${{matrix.language}}" |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,20 @@ | ||
| name: Greetings | ||
|
|
||
| on: | ||
| pull_request_target: | ||
| types: [opened] | ||
| issues: | ||
| types: [opened] | ||
|
|
||
| jobs: | ||
| greeting: | ||
| runs-on: ubuntu-latest | ||
| permissions: | ||
| issues: write | ||
| pull-requests: write | ||
| steps: | ||
| - uses: actions/first-interaction@v1 | ||
| with: | ||
| repo-token: ${{ secrets.GITHUB_TOKEN }} | ||
| issue-message: 'Welcome to the EV Grid Oracle repository! Thank you for opening your first issue. Our team will review it shortly. Please ensure you have read our CONTRIBUTING.md.' | ||
| pr-message: 'Welcome to the EV Grid Oracle repository! Thank you for your first pull request. A maintainer will review it soon. Please ensure your PR follows our guidelines in CONTRIBUTING.md.' |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,15 @@ | ||
| name: "Pull Request Labeler" | ||
| on: | ||
| - pull_request_target | ||
|
|
||
| jobs: | ||
| triage: | ||
| permissions: | ||
| contents: read | ||
| pull-requests: write | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/labeler@v5 | ||
| with: | ||
| repo-token: "${{ secrets.GITHUB_TOKEN }}" | ||
| configuration-path: .github/labeler.yml |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,46 @@ | ||
| name: Deploy GitHub Pages | ||
|
|
||
| on: | ||
| workflow_run: | ||
| workflows: ["Repository Health Dashboard"] | ||
| types: | ||
| - completed | ||
| branches: | ||
| - main | ||
|
|
||
| permissions: | ||
| contents: read | ||
| pages: write | ||
| id-token: write | ||
|
|
||
| concurrency: | ||
| group: "pages" | ||
| cancel-in-progress: false | ||
|
|
||
| jobs: | ||
| deploy: | ||
| environment: | ||
| name: github-pages | ||
| url: ${{ steps.deployment.outputs.page_url }} | ||
| runs-on: ubuntu-latest | ||
| if: ${{ github.event.workflow_run.conclusion == 'success' }} | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🛡️ Detected with Advanced Tier | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- workflow files ---'
git ls-files '.github/workflows/*'
printf '%s\n' '--- pages workflow ---'
cat -n .github/workflows/pages.yml
printf '%s\n' '--- directly related workflow references ---'
rg -n -C 3 'workflow_run|health-dashboard|deploy-pages|pages:' .github/workflows .github 2>/dev/null || trueRepository: NITISH-R-G/ev-grid-oracle Length of output: 6422 🌐 Web query:
💡 Result: Inspection citation: inspection_642608ba63b50c68f142b8d1f5c8b91a <source_evidence> Citations:
🌐 Web query:
💡 Result: Inspection citation: inspection_36a9c5f73044025c940e956c294d75c1 <source_evidence> Citations:
XSS Reachability: External Exclude pull request runs before deploying the dashboard.
Add 🤖 Prompt for AI Agents |
||
| steps: | ||
| - name: Download artifacts | ||
| uses: actions/download-artifact@v4 | ||
| with: | ||
| name: health-dashboard | ||
| path: ./public | ||
| github-token: ${{ secrets.GITHUB_TOKEN }} | ||
| run-id: ${{ github.event.workflow_run.id }} | ||
|
|
||
| - name: Setup Pages | ||
| uses: actions/configure-pages@v5 | ||
|
|
||
| - name: Upload artifact | ||
| uses: actions/upload-pages-artifact@v3 | ||
| with: | ||
| path: ./public | ||
|
|
||
| - name: Deploy to GitHub Pages | ||
| id: deployment | ||
| uses: actions/deploy-pages@v4 | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,64 @@ | ||
| name: Repository Maintenance Automation | ||
|
|
||
| on: | ||
| push: | ||
| branches: [ "main", "master" ] | ||
| pull_request: | ||
| branches: [ "main", "master" ] | ||
| schedule: | ||
| - cron: '0 2 * * *' # Daily at 2 AM UTC | ||
|
|
||
| permissions: | ||
| contents: write | ||
|
|
||
| jobs: | ||
| maintenance: | ||
| runs-on: ubuntu-latest | ||
| if: github.event_name == 'push' || github.event_name == 'schedule' || github.event.pull_request.head.repo.full_name == github.repository | ||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v4 | ||
| with: | ||
| ref: ${{ github.head_ref || github.ref }} | ||
| fetch-depth: 0 | ||
|
|
||
| - name: Set up Python | ||
| uses: actions/setup-python@v5 | ||
| with: | ||
| python-version: '3.12' | ||
|
|
||
| - name: Install dependencies | ||
| run: | | ||
| python -m pip install --upgrade pip uv | ||
| uv pip install --system -e ".[dev,demo]" | ||
| uv pip install --system cyclonedx-bom | ||
|
|
||
| - name: Auto-fix linting and formatting (Ruff) | ||
| run: | | ||
| uv run --with ruff ruff check --unsafe-fixes --fix . | ||
|
Comment on lines
+32
to
+38
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🩺 Stability & Availability | 🟠 Major | 🏗️ Heavy lift 🔎 Supported by static analysis🏁 Script executed: sed -n '1,90p' .github/workflows/repo-maintenance.yml
rg -n '^\[tool\.ruff|select|ignore|lint' pyproject.toml ruff.toml .ruff.toml 2>/dev/nullRepository: NITISH-R-G/ev-grid-oracle Length of output: 2160 🏁 Script executed: #!/bin/bash
set +e
printf '%s\n' '--- Ruff configuration and project pins ---'
sed -n '1,130p' .ruff.toml
sed -n '1,130p' pyproject.toml
printf '%s\n' '--- available tooling ---'
command -v uv || true
command -v ruff || true
ruff --version 2>/dev/null || true
uv --version 2>/dev/null || true
printf '%s\n' '--- current Ruff diagnostics (read-only) ---'
if command -v ruff >/dev/null 2>&1; then
ruff check --output-format=concise .
printf 'ruff_check_exit=%s\n' "$?"
printf '%s\n' '--- fixable diff preview (does not write files) ---'
ruff check --unsafe-fixes --fix --diff --output-format=concise .
printf 'ruff_fix_diff_exit=%s\n' "$?"
else
printf '%s\n' 'ruff unavailable'
fi
printf '%s\n' '--- likely handler references ---'
rg -n -i 'handler|comment-1|two handlers' --glob '*.py' --glob '*.yml' --glob '*.yaml' . | head -120
exit 0Repository: NITISH-R-G/ev-grid-oracle Length of output: 9961 🏁 Script executed: #!/bin/bash
set +e
tmp="$(mktemp -d)"
trap 'rm -rf "$tmp"' EXIT
git ls-files -z | tar --null -cf - -T - | tar -xf - -C "$tmp"
printf '%s\n' '--- Ruff diagnostics after workflow fix mode in isolated copy ---'
ruff check --unsafe-fixes --fix "$tmp"
fix_status=$?
printf 'fix_command_exit=%s\n' "$fix_status"
ruff check --output-format=concise "$tmp"
check_status=$?
printf 'post_fix_check_exit=%s\n' "$check_status"
exit 0Repository: NITISH-R-G/ev-grid-oracle Length of output: 40868 Do not make artifact generation depend on a failing whole-tree Ruff check. 🤖 Prompt for AI Agents |
||
| uv run --with ruff ruff format . | ||
|
|
||
| - name: Generate SBOM | ||
| run: | | ||
| uv run cyclonedx-py environment -o bom.json | ||
|
|
||
| - name: Generate Documentation (Docs Sync) | ||
| run: | | ||
| python tools/docs_sync.py | ||
|
|
||
| - name: Generate Architecture Diagram | ||
| run: | | ||
| python tools/generate_architecture_diagrams.py | ||
|
|
||
| - name: Generate Knowledge Graph | ||
| run: | | ||
| python tools/generate_knowledge_graph.py | ||
|
|
||
| - name: Commit changes | ||
| run: | | ||
| git config --global user.name 'github-actions[bot]' | ||
| git config --global user.email 'github-actions[bot]@users.noreply.github.com' | ||
| git add -f artifacts/ docs/api/ || true | ||
| git add . | ||
| git commit -m "chore(auto): repo maintenance (autofix, docs, graphs, sbom)" || echo "No changes to commit" | ||
| git push | ||
| Original file line number | Diff line number | Diff line change | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,21 @@ | ||||||||||||||||
| name: Mark stale issues and pull requests | ||||||||||||||||
|
|
||||||||||||||||
| on: | ||||||||||||||||
| schedule: | ||||||||||||||||
| - cron: '30 1 * * *' | ||||||||||||||||
|
|
||||||||||||||||
| jobs: | ||||||||||||||||
| stale: | ||||||||||||||||
| runs-on: ubuntu-latest | ||||||||||||||||
| permissions: | ||||||||||||||||
| issues: write | ||||||||||||||||
| pull-requests: write | ||||||||||||||||
|
Comment on lines
+10
to
+12
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win 🔎 Supported by static analysis🌐 Web query:
💡 Result: <source_evidence> Citations:
🏁 Script executed: sed -n '1,80p' .github/workflows/stale.ymlRepository: NITISH-R-G/ev-grid-oracle Length of output: 1002 Grant
Proposed fix permissions:
+ actions: write
issues: write
pull-requests: write📝 Committable suggestion
Suggested change
🧰 Tools🪛 zizmor (1.30.0)[warning] 1-21: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block (excessive-permissions) [warning] 11-11: permissions without explanatory comments (undocumented-permissions): needs an explanatory comment (undocumented-permissions) 🤖 Prompt for AI Agents |
||||||||||||||||
| steps: | ||||||||||||||||
| - uses: actions/stale@v9 | ||||||||||||||||
| with: | ||||||||||||||||
| stale-issue-message: 'This issue is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 7 days.' | ||||||||||||||||
| stale-pr-message: 'This PR is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 7 days.' | ||||||||||||||||
| close-issue-message: 'This issue was closed because it has been stalled for 7 days with no activity.' | ||||||||||||||||
| close-pr-message: 'This PR was closed because it has been stalled for 7 days with no activity.' | ||||||||||||||||
| days-before-stale: 60 | ||||||||||||||||
| days-before-close: 7 | ||||||||||||||||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,21 @@ | ||
| repos: | ||
| - repo: https://github.com/pre-commit/pre-commit-hooks | ||
| rev: v4.5.0 | ||
| hooks: | ||
| - id: trailing-whitespace | ||
| - id: end-of-file-fixer | ||
| - id: check-yaml | ||
| - id: check-added-large-files | ||
|
|
||
| - repo: https://github.com/astral-sh/ruff-pre-commit | ||
| rev: v0.3.5 | ||
| hooks: | ||
| - id: ruff | ||
| args: [ --fix ] | ||
| - id: ruff-format | ||
|
|
||
| - repo: https://github.com/pre-commit/mirrors-prettier | ||
| rev: v3.1.0 | ||
| hooks: | ||
| - id: prettier | ||
| types_or: [javascript, jsx, ts, tsx, json, markdown] |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🛡️ Detected with Advanced Tier | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: NITISH-R-G/ev-grid-oracle
Length of output: 4653
🏁 Script executed:
Repository: NITISH-R-G/ev-grid-oracle
Length of output: 7061
🏁 Script executed:
Repository: NITISH-R-G/ev-grid-oracle
Length of output: 7061
🏁 Script executed:
Repository: NITISH-R-G/ev-grid-oracle
Length of output: 7061
Security Misconfiguration
Reachability: External
Exploitability: Difficult
CWE: CWE-829 — Inclusion of Functionality from Untrusted Control Sphere
Pin every GitHub Actions reference to a reviewed full commit SHA.
Mutable tags can resolve to remotely changed action code at run time. The affected workflows include jobs with write permissions, such as
ai-review.yml,repo-maintenance.yml,greetings.yml,labeler.yml,stale.yml,pages.yml, and CodeQL'ssecurity-events: writepermission. A compromised action could use those credentials to modify repository content, issues, pull requests, security results, or Pages deployments.The listed references should be pinned, but this correction must cover every mutable
uses:reference. The repository also contains mutable references inhealth-dashboard.yml,code-quality.yml, andsecurity.yml, includingtrufflesecurity/trufflehog@mainandaquasecurity/trivy-action@master. Keep a reviewed version comment beside each full SHA.🧰 Tools
🪛 zizmor (1.30.0)
[warning] 1-22: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block
(excessive-permissions)
[error] 21-21: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
🤖 Prompt for AI Agents